Eleven Drainer
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5ea6FV…bNhSSummary
Eleven Drainer is a Drainer-as-a-Service (DaaS) toolkit and phishing syndicate that emerged around August 2025, offering rented wallet-draining infrastructure to criminal operators who deploy it through phishing sites, DNS hijacks, and compromised front-ends. The kit is associated with confirmed theft of at least $4.2 million across a three-week window in November 2025, including a $700,000 loss from a DNS hijack of decentralized exchanges Aerodrome and Velodrome. As of June 2026, the kit remains active and was detected embedded in a compromised Gitcoin subdomain.
Connected Entities
6 entities · 60 linked investigations- wallet drainers→mentioned with→Ethereum(70%)
- Eleven Drainer→mentioned with→Ethereum(60%)
- Aerodrome Finance→mentioned with→Ethereum(80%)
- Inferno Drainer→mentioned with→Ethereum(70%)
- Inferno Drainer→mentioned with→Vanilla Drainer (DaaS)(75%)
- Eleven Drainer→mentioned with→Inferno Drainer(80%)
- Eleven Drainer→mentioned with→wallet drainers(80%)
- wallet drainers→mentioned with→Inferno Drainer(80%)
- Vanilla Drainer (DaaS)→mentioned with→Inferno Drainer(80%)
- Vanilla Drainer (DaaS)→mentioned with→Eleven Drainer(80%)
- + 4 more
Timeline(6 events)
August 2025
Eleven Drainer toolkit alleged to have launched, based on community research placing its origin approximately August 2025. Exact launch date is unconfirmed.
BITBBQ community research6 November 2025
Largest cluster of Eleven Drainer drain activity observed, with the majority of the confirmed $4.2 million in November losses occurring between November 6 and November 8, 2025.
BITBBQ community research9 November 2025
SlowMist founder Yu Xian publicly identifies a growing cluster of victims linked to Eleven Drainer, marking the first major public disclosure of the operation.
BeInCrypto21 November 2025
Eleven Drainer code deployed in a DNS hijack of Aerodrome Finance and Velodrome Finance via a compromised NameSilo registrar account. Attackers stripped DNSSEC and redirected both protocol frontends to a phishing interface. Approximately $700,000 was stolen; an estimated $3.5 million in additional losses was prevented by Blockaid's detection network.
CoinDesk; Blockaid Blog24 November 2025
Extended community on-chain analysis published, identifying ENS addresses, admin wallets, fee laundering addresses, and the scam-as-a-service fee structure (approximately 15 percent to operators).
CryptoSafetyFirst CW48 2025 digest21 June 2026
Blockaid detects Eleven Drainer code embedded in the Gitcoin subdomain files.gitcoin.co via a frontend attack. Blockaid advises users not to interact with the site. The incident confirms the toolkit remains active more than seven months after its initial public identification.
Blockaid on X; Phemex NewsDecision Log
- hash: DvnJFnt2uGzkyebhDecDFZN7LSGeN9VRdtRkwKo4ryww
This investigation is cryptographically anchored to the Solana blockchain (1 event). 17 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/26/2026, 5:12:15 PM
last updated: 7/30/2026, 10:29:55 PM
3 viewsavoid.net — verified advice for a post-truth world